Atomicorp WAF Research Notes

Research Update - 2026-09-16

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-0768Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code340095
CVE-2026-61560@zereight/mcp-gitlab's unauthenticated arbitrary file read via upload_markdown enables PAT exfiltration and full accou340007 , 344360 , 347009 , 390709
CVE-2026-62379OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-61559@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-61568@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport390719
CVE-2023-54398Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614
CVE-2024-58385Yonyou U8 CRM SQL Injection via fillbacksettingedit.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-89026Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-89308Arbitrary command execution in TrxTimeATTENDANCE340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-91931Flowise before 3.1.4 Remote Code Execution via Custom MCP npx340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-52484MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 Arbitrary Code Execution Vulnerability340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-91935Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes310047 , 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-91940crawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategy340007 , 344360 , 390709
CVE-2026-91989atomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.py340007 , 344360 , 347009 , 390709
CVE-2026-44203OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-54549Meta Ads MCP: Server-Side Request Forgery (SSRF) in upload_ad_image via Unrestricted image_url Fetch334168 , 390719
CVE-2026-91943Crawl4AI before 0.9.3 SSRF via PDFContentScrapingStrategy337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-79425CRMEB v6.0.0 Server-Side Request Forgery Vulnerability337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-55864GeoNetwork: Unauthenticaded Server-Side Request Forgery in SLD Tool337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-76820OpenCTI: Synchronizer SSRF: stream fetch has no URL validation337109 , 337110 , 344360 , 390719 , 398021 , 398022
CVE-2026-54544Fireshare has unauthenticated SSRF via missing login_required on webhook test endpoints337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-54077ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-58485mcp-searxng: DNS-resolved Private Hostname SSRF in web_url_read337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-58502githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-91966AVideo through 29.0 Unauthenticated SSRF via Host Header337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-54688mcp-searxng: SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-886181024-lab SmartAdmin v3.30.0 Arbitrary Code Execution Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-62280OpenAM Reflected XSS in the OAuth2/OIDC wap consent page333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-55591Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-91848WuzhiCMS index.php getDataOfJson sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-32599Netmaker has a boolean‑based SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-44202OpenAM Authenticated Server-Side Request Forgery (SSRF) via /sessionservice337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-91922Steedos Platform through 3.0.15-beta.47 Reflected XSS via page render333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-91967AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-92184ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-91944crawl4ai before 0.9.3 DOM-based XSS via Playground UI333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-55374canto-saas-api: Authenticated API requests can be redirected via unencoded path variables340162 , 340163 , 340165 , 344365
CVE-2025-10012Portabilis i-Educar educar_historico_escolar_lst.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9236Portabilis i-Educar Tipos de usuàrio educar_tipo_usuario_lst.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9531Portabilis i-Educar Agenda agenda.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9606Portabilis i-Educar agenda_preferencias.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-91849WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload351000
CVE-2026-91853TOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-91854code-projects Record Management System reg.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148